Microsoft Defender for Cloud Regulatory Compliance not showing enabled standards despite Azure Policy evaluations

Grax Mon 0 Reputation points
2026-09-29T06:28:14.9733333+00:00

I am working with an Azure subscription and have enabled/assigned several compliance standards at subscription scope, including ISO 27001:2013, ISO/IEC 27001:2022, ISO/IEC 27002:2022, and SOC 2 Type 2.

This is a personal, fictional Azure lab environment created for learning and GRC practice; it is not a production environment or an actual financial institution.

Azure Policy is actively evaluating these assignments and returning compliance results. For example:

ISO 27001:2013: 3/17 compliant (18%)

ISO/IEC 27002:2022: 23/46 compliant (50%)

Require a tag on resources: 20/27 compliant (74%)

Allowed locations: 27/27 compliant (100%)

In Microsoft Defender for Cloud → Environment settings → Security Standards, the relevant standards are also shown as enabled at the subscription level.

However, Microsoft Defender for Cloud → Regulatory Compliance continues to show that there are no additional standards being monitored / no subscription available for compliance calculation. The additional standards do not appear in the Regulatory Compliance overview.

I have already:

Verified that the policy assignments exist at subscription scope.

Verified that the assignments are actively producing compliance evaluations.

Verified that the relevant standards are enabled in Defender for Cloud.

Refreshed and revisited the Regulatory Compliance views.

Reviewed the separate law-falconpay Log Analytics workspace scope in Defender for Cloud.

The issue persists.

Is there an additional configuration, synchronization step, or prerequisite required for Defender for Cloud Regulatory Compliance to recognize these subscription-level standards, or could this potentially be a portal/service issue?

I can provide screenshots of the Security Standards, Policy assignments/compliance results, and Regulatory Compliance pages if required.

Microsoft Defender for Cloud Regulatory Compliance not showing enabled standards despite Azure Policy evaluations

I am working with an Azure subscription and have enabled/assigned several compliance standards at subscription scope, including ISO 27001:2013, ISO/IEC 27001:2022, ISO/IEC 27002:2022, and SOC 2 Type 2.

This is a personal, fictional Azure lab environment created for learning and GRC practice; it is not a production environment or an actual financial institution.

Azure Policy is actively evaluating these assignments and returning compliance results. For example:

ISO 27001:2013: 3/17 compliant (18%)

ISO/IEC 27002:2022: 23/46 compliant (50%)

Require a tag on resources: 20/27 compliant (74%)

Allowed locations: 27/27 compliant (100%)

In Microsoft Defender for Cloud → Environment settings → Security Standards, the relevant standards are also shown as enabled at the subscription level.

However, Microsoft Defender for Cloud → Regulatory Compliance continues to show that there are no additional standards being monitored / no subscription available for compliance calculation. The additional standards do not appear in the Regulatory Compliance overview.

I have already:

Verified that the policy assignments exist at subscription scope.

Verified that the assignments are actively producing compliance evaluations.

Verified that the relevant standards are enabled in Defender for Cloud.

Refreshed and revisited the Regulatory Compliance views.

Reviewed the separate law-falconpay Log Analytics workspace scope in Defender for Cloud.

The issue persists.

Is there an additional configuration, synchronization step, or prerequisite required for Defender for Cloud Regulatory Compliance to recognize these subscription-level standards, or could this potentially be a portal/service issue?

I can provide screenshots of the Security Standards, Policy assignments/compliance results, and Regulatory Compliance pages if required.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.